Here's a different way to botch reg:
Break into the attendees social networking accounts to send spam. (http://www.wired.com/underwire/2013/10/new-york-comic-con-twitter-rfid/)
Comic-Con tried that. They got very bad press.
That's a potential mistake to avoid.
I agree this was a mistake on NYCC part but it was also a major blunder on the attendees part in agreeing to the terms of using their social networking accounts to register.